Microsoft Security Response Center 한국어 팔로우 "CVE-2026-59995 OpenSSH 10.4 이전 버전의 sftp는 "sftp server:/path ."를 공격자가 제어하는 서버와 함께 사용할 때 다운로드된 파일의 위치를 제대로 제한하지 않습니다." CVE-2026-59995 sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server. msrc.microsoft.com